Your DORA questions answered – Business resilience more broadly
This fifth of a series of articles covering a practical session organised by Ashurst focuses on business resilience questions connected to DORA.
DORA Article 30(2)-(3) outlines the minimum elements that must be included in any contractual arrangements on the use of ICT services:
The policy needs to specify that the contractual arrangements must include:
The final responsibility for inspection, audit and testing rests with the financial entity who can employ the following in order to carry these out:
The financial entity cannot only rely on third party certification or reports supplied by the ICT third-party service provider and these can only be used if the financial entity:
Any material changes to these arrangements must be:
By all parties
Your DORA questions answered – Business resilience more broadly
This fifth of a series of articles covering a practical session organised by Ashurst focuses on business resilience questions connected to DORA.
Thomas Hyrkiel3 min read
Your DORA questions answered – CIFs
This third of a series of six articles covering a practical session organised by Ashurst focuses on critical or important functions.
Thomas Hyrkiel4 min read
Your DORA questions answered – Extraterritoriality and interaction with existing rules
This last of a series of six articles covering a practical session organised by Ashurst focuses on how DORA will interact with existing rules as well as its extraterritorial effects.
Thomas Hyrkiel3 min read
Technology
Your DORA questions answered – Business resilience more broadly
Technology
Your DORA questions answered – CIFs
Technology
Your DORA questions answered – Extraterritoriality and interaction with existing rules
As regulators move from trialling AI to active oversight, firms face pressure to build governance structures to withstand scrutiny across multiple jurisdictions.
Vlada Gurvich37 min listen
Norway’s financial infrastructure remains resilient, but rising cyber threats, third-party dependencies, and operational risks are rapidly changing the landscape.
Vasilka Lalevska4 min read
Joint Committee report underlines cyber risks, ESG data, and consumer protection as core compliance priorities.
Vasilka Lalevska1 min read
While the digital omnibuses simplify rules, the Commission's Digital Fitness Check assesses the coherence of the EU digital rulebook.
Vasilka Lalevska3 min read
AI has been the catalyst for an infrastructure rethink.
Carmen Cracknell1 min read
Regulation to push European businesses and third-country suppliers to consider potential exposure to government influence when assessing their technology vendor relationships.
Proposals reflect established international approaches to operational resilience and will be familiar to Authorized Firms that are already subject to regimes in the UK and EU.
Gabriella Savastano | CMS, Caoimhe Crowley | CMS4 min read
In a challenging cybersecurity landscape, the organization’s role today has never been more relevant.
Vasilka Lalevska2 min read
Further Reading